2 * Copyright (C) 2011 EfficiOS Inc.
4 * SPDX-License-Identifier: GPL-2.0-only
9 #include "condition-internal.hpp"
10 #include "consumer.hpp"
11 #include "event-notifier-error-accounting.hpp"
12 #include "kern-modules.hpp"
13 #include "kernel-consumer.hpp"
15 #include "lttng-sessiond.hpp"
16 #include "lttng-syscall.hpp"
17 #include "modprobe.hpp"
18 #include "notification-thread-commands.hpp"
20 #include "sessiond-config.hpp"
21 #include "tracker.hpp"
24 #include <common/common.hpp>
25 #include <common/hashtable/utils.hpp>
26 #include <common/kernel-ctl/kernel-ctl.hpp>
27 #include <common/kernel-ctl/kernel-ioctl.hpp>
28 #include <common/sessiond-comm/sessiond-comm.hpp>
29 #include <common/trace-chunk.hpp>
30 #include <common/tracker.hpp>
31 #include <common/urcu.hpp>
32 #include <common/utils.hpp>
34 #include <lttng/condition/event-rule-matches-internal.hpp>
35 #include <lttng/condition/event-rule-matches.h>
36 #include <lttng/event-rule/event-rule-internal.hpp>
37 #include <lttng/event-rule/event-rule.h>
38 #include <lttng/event-rule/kernel-uprobe-internal.hpp>
39 #include <lttng/event.h>
40 #include <lttng/lttng-error.h>
41 #include <lttng/tracker.h>
42 #include <lttng/userspace-probe-internal.hpp>
43 #include <lttng/userspace-probe.h>
50 #include <sys/types.h>
54 * Key used to reference a channel between the sessiond and the consumer. This
55 * is only read and updated with the session_list lock held.
57 static uint64_t next_kernel_channel_key
;
59 static const char *module_proc_lttng
= "/proc/lttng";
61 static int kernel_tracer_fd
= -1;
62 static int kernel_tracer_event_notifier_group_fd
= -1;
63 static int kernel_tracer_event_notifier_group_notification_fd
= -1;
64 static struct cds_lfht
*kernel_token_to_event_notifier_rule_ht
;
68 * On some architectures, calling convention details are embedded in the symbol
69 * addresses. Uprobe requires a "clean" symbol offset (or at least, an address
70 * where an instruction boundary would be legal) to add
71 * instrumentation. sanitize_uprobe_offset implements that sanitization logic on
72 * a per-architecture basis.
74 #if defined(__arm__) || defined(__aarch64__)
75 static inline uint64_t sanitize_uprobe_offset(uint64_t raw_offset
)
78 * The least significant bit is used when branching to switch to thumb
79 * ISA. However, it's an invalid address for us; mask the least
82 return raw_offset
&= ~0b1;
84 #else /* defined(__arm__) || defined(__aarch64__) */
85 static inline uint64_t sanitize_uprobe_offset(uint64_t raw_offset
)
93 * Add context on a kernel channel.
95 * Assumes the ownership of ctx.
97 int kernel_add_channel_context(struct ltt_kernel_channel
*chan
, struct ltt_kernel_context
*ctx
)
104 DBG("Adding context to channel %s", chan
->channel
->name
);
105 ret
= kernctl_add_context(chan
->fd
, &ctx
->ctx
);
109 /* Exists but not available for this kernel */
110 ret
= LTTNG_ERR_KERN_CONTEXT_UNAVAILABLE
;
113 /* If EEXIST, we just ignore the error */
117 PERROR("add context ioctl");
118 ret
= LTTNG_ERR_KERN_CONTEXT_FAIL
;
125 cds_list_add_tail(&ctx
->list
, &chan
->ctx_list
);
130 trace_kernel_destroy_context(ctx
);
136 * Create a new kernel session, register it to the kernel tracer and add it to
137 * the session daemon session.
139 int kernel_create_session(struct ltt_session
*session
)
142 struct ltt_kernel_session
*lks
;
144 LTTNG_ASSERT(session
);
146 /* Allocate data structure */
147 lks
= trace_kernel_create_session();
148 if (lks
== nullptr) {
153 /* Kernel tracer session creation */
154 ret
= kernctl_create_session(kernel_tracer_fd
);
156 PERROR("ioctl kernel create session");
161 /* Prevent fd duplication after execlp() */
162 ret
= fcntl(lks
->fd
, F_SETFD
, FD_CLOEXEC
);
164 PERROR("fcntl session fd");
167 lks
->id
= session
->id
;
168 lks
->consumer_fds_sent
= 0;
169 session
->kernel_session
= lks
;
171 DBG("Kernel session created (fd: %d)", lks
->fd
);
174 * This is necessary since the creation time is present in the session
175 * name when it is generated.
177 if (session
->has_auto_generated_name
) {
178 ret
= kernctl_session_set_name(lks
->fd
, DEFAULT_SESSION_NAME
);
180 ret
= kernctl_session_set_name(lks
->fd
, session
->name
);
183 WARN("Could not set kernel session name for session %" PRIu64
" name: %s",
188 ret
= kernctl_session_set_creation_time(lks
->fd
, session
->creation_time
);
190 WARN("Could not set kernel session creation time for session %" PRIu64
" name: %s",
199 trace_kernel_destroy_session(lks
);
200 trace_kernel_free_session(lks
);
206 * Create a kernel channel, register it to the kernel tracer and add it to the
209 int kernel_create_channel(struct ltt_kernel_session
*session
, struct lttng_channel
*chan
)
212 struct ltt_kernel_channel
*lkc
;
214 LTTNG_ASSERT(session
);
217 /* Allocate kernel channel */
218 lkc
= trace_kernel_create_channel(chan
);
219 if (lkc
== nullptr) {
223 DBG3("Kernel create channel %s with attr: %d, %" PRIu64
", %" PRIu64
", %u, %u, %d, %d",
225 lkc
->channel
->attr
.overwrite
,
226 lkc
->channel
->attr
.subbuf_size
,
227 lkc
->channel
->attr
.num_subbuf
,
228 lkc
->channel
->attr
.switch_timer_interval
,
229 lkc
->channel
->attr
.read_timer_interval
,
230 lkc
->channel
->attr
.live_timer_interval
,
231 lkc
->channel
->attr
.output
);
233 /* Kernel tracer channel creation */
234 ret
= kernctl_create_channel(session
->fd
, &lkc
->channel
->attr
);
236 PERROR("ioctl kernel create channel");
240 /* Setup the channel fd */
242 /* Prevent fd duplication after execlp() */
243 ret
= fcntl(lkc
->fd
, F_SETFD
, FD_CLOEXEC
);
245 PERROR("fcntl session fd");
248 /* Add channel to session */
249 cds_list_add(&lkc
->list
, &session
->channel_list
.head
);
250 session
->channel_count
++;
251 lkc
->session
= session
;
252 lkc
->key
= ++next_kernel_channel_key
;
254 DBG("Kernel channel %s created (fd: %d, key: %" PRIu64
")",
270 * Create a kernel event notifier group, register it to the kernel tracer and
271 * add it to the kernel session.
273 static int kernel_create_event_notifier_group(int *event_notifier_group_fd
)
278 LTTNG_ASSERT(event_notifier_group_fd
);
280 /* Kernel event notifier group creation. */
281 ret
= kernctl_create_event_notifier_group(kernel_tracer_fd
);
283 PERROR("Failed to create kernel event notifier group");
290 /* Prevent fd duplication after execlp(). */
291 ret
= fcntl(local_fd
, F_SETFD
, FD_CLOEXEC
);
293 PERROR("Failed to set FD_CLOEXEC on kernel event notifier group file descriptor: fd = %d",
298 DBG("Created kernel event notifier group: fd = %d", local_fd
);
299 *event_notifier_group_fd
= local_fd
;
304 ret
= close(local_fd
);
306 PERROR("Failed to close kernel event notifier group file descriptor: fd = %d",
315 * Compute the offset of the instrumentation byte in the binary based on the
316 * function probe location using the ELF lookup method.
318 * Returns 0 on success and set the offset out parameter to the offset of the
320 * Returns -1 on error
322 static int extract_userspace_probe_offset_function_elf(
323 const struct lttng_userspace_probe_location
*probe_location
,
330 const char *symbol
= nullptr;
331 const struct lttng_userspace_probe_location_lookup_method
*lookup
= nullptr;
332 enum lttng_userspace_probe_location_lookup_method_type lookup_method_type
;
334 LTTNG_ASSERT(lttng_userspace_probe_location_get_type(probe_location
) ==
335 LTTNG_USERSPACE_PROBE_LOCATION_TYPE_FUNCTION
);
337 lookup
= lttng_userspace_probe_location_get_lookup_method(probe_location
);
343 lookup_method_type
= lttng_userspace_probe_location_lookup_method_get_type(lookup
);
345 LTTNG_ASSERT(lookup_method_type
==
346 LTTNG_USERSPACE_PROBE_LOCATION_LOOKUP_METHOD_TYPE_FUNCTION_ELF
);
348 symbol
= lttng_userspace_probe_location_function_get_function_name(probe_location
);
354 fd
= lttng_userspace_probe_location_function_get_binary_fd(probe_location
);
360 ret
= run_as_extract_elf_symbol_offset(fd
, symbol
, uid
, gid
, offset
);
362 DBG("userspace probe offset calculation failed for "
368 DBG("userspace probe elf offset for %s is 0x%jd", symbol
, (intmax_t) (*offset
));
374 * Compute the offsets of the instrumentation bytes in the binary based on the
375 * tracepoint probe location using the SDT lookup method. This function
376 * allocates the offsets buffer, the caller must free it.
378 * Returns 0 on success and set the offset out parameter to the offsets of the
380 * Returns -1 on error.
382 static int extract_userspace_probe_offset_tracepoint_sdt(
383 const struct lttng_userspace_probe_location
*probe_location
,
387 uint32_t *offsets_count
)
389 enum lttng_userspace_probe_location_lookup_method_type lookup_method_type
;
390 const struct lttng_userspace_probe_location_lookup_method
*lookup
= nullptr;
391 const char *probe_name
= nullptr, *provider_name
= nullptr;
395 LTTNG_ASSERT(lttng_userspace_probe_location_get_type(probe_location
) ==
396 LTTNG_USERSPACE_PROBE_LOCATION_TYPE_TRACEPOINT
);
398 lookup
= lttng_userspace_probe_location_get_lookup_method(probe_location
);
404 lookup_method_type
= lttng_userspace_probe_location_lookup_method_get_type(lookup
);
406 LTTNG_ASSERT(lookup_method_type
==
407 LTTNG_USERSPACE_PROBE_LOCATION_LOOKUP_METHOD_TYPE_TRACEPOINT_SDT
);
409 probe_name
= lttng_userspace_probe_location_tracepoint_get_probe_name(probe_location
);
415 provider_name
= lttng_userspace_probe_location_tracepoint_get_provider_name(probe_location
);
416 if (!provider_name
) {
421 fd
= lttng_userspace_probe_location_tracepoint_get_binary_fd(probe_location
);
427 ret
= run_as_extract_sdt_probe_offsets(
428 fd
, provider_name
, probe_name
, uid
, gid
, offsets
, offsets_count
);
430 DBG("userspace probe offset calculation failed for sdt "
437 if (*offsets_count
== 0) {
438 DBG("no userspace probe offset found");
442 DBG("%u userspace probe SDT offsets found for %s:%s at:",
446 for (i
= 0; i
< *offsets_count
; i
++) {
447 DBG("\t0x%jd", (intmax_t) ((*offsets
)[i
]));
453 static int userspace_probe_add_callsite(const struct lttng_userspace_probe_location
*location
,
458 const struct lttng_userspace_probe_location_lookup_method
*lookup_method
= nullptr;
459 enum lttng_userspace_probe_location_lookup_method_type type
;
462 lookup_method
= lttng_userspace_probe_location_get_lookup_method(location
);
463 if (!lookup_method
) {
468 type
= lttng_userspace_probe_location_lookup_method_get_type(lookup_method
);
470 case LTTNG_USERSPACE_PROBE_LOCATION_LOOKUP_METHOD_TYPE_FUNCTION_ELF
:
472 struct lttng_kernel_abi_event_callsite callsite
;
475 ret
= extract_userspace_probe_offset_function_elf(location
, uid
, gid
, &offset
);
477 ret
= LTTNG_ERR_PROBE_LOCATION_INVAL
;
481 callsite
.u
.uprobe
.offset
= sanitize_uprobe_offset(offset
);
482 ret
= kernctl_add_callsite(fd
, &callsite
);
484 WARN("Failed to add callsite to ELF userspace probe.");
485 ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
490 case LTTNG_USERSPACE_PROBE_LOCATION_LOOKUP_METHOD_TYPE_TRACEPOINT_SDT
:
493 uint64_t *offsets
= nullptr;
494 uint32_t offsets_count
;
495 struct lttng_kernel_abi_event_callsite callsite
;
498 * This call allocates the offsets buffer. This buffer must be freed
501 ret
= extract_userspace_probe_offset_tracepoint_sdt(
502 location
, uid
, gid
, &offsets
, &offsets_count
);
504 ret
= LTTNG_ERR_PROBE_LOCATION_INVAL
;
507 for (i
= 0; i
< offsets_count
; i
++) {
508 callsite
.u
.uprobe
.offset
= sanitize_uprobe_offset(offsets
[i
]);
509 ret
= kernctl_add_callsite(fd
, &callsite
);
511 WARN("Failed to add callsite to SDT userspace probe");
512 ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
521 ret
= LTTNG_ERR_PROBE_LOCATION_INVAL
;
529 * Extract the offsets of the instrumentation point for the different lookup
532 static int userspace_probe_event_add_callsites(struct lttng_event
*ev
,
533 struct ltt_kernel_session
*session
,
537 const struct lttng_userspace_probe_location
*location
= nullptr;
540 LTTNG_ASSERT(ev
->type
== LTTNG_EVENT_USERSPACE_PROBE
);
542 location
= lttng_event_get_userspace_probe_location(ev
);
548 ret
= userspace_probe_add_callsite(location
, session
->uid
, session
->gid
, fd
);
550 WARN("Failed to add callsite to userspace probe event '%s'", ev
->name
);
558 * Extract the offsets of the instrumentation point for the different look-up
561 static int userspace_probe_event_rule_add_callsites(const struct lttng_event_rule
*rule
,
562 const struct lttng_credentials
*creds
,
566 enum lttng_event_rule_status status
;
567 enum lttng_event_rule_type event_rule_type
;
568 const struct lttng_userspace_probe_location
*location
= nullptr;
573 event_rule_type
= lttng_event_rule_get_type(rule
);
574 LTTNG_ASSERT(event_rule_type
== LTTNG_EVENT_RULE_TYPE_KERNEL_UPROBE
);
576 status
= lttng_event_rule_kernel_uprobe_get_location(rule
, &location
);
577 if (status
!= LTTNG_EVENT_RULE_STATUS_OK
|| !location
) {
582 ret
= userspace_probe_add_callsite(
583 location
, lttng_credentials_get_uid(creds
), lttng_credentials_get_gid(creds
), fd
);
585 WARN("Failed to add callsite to user space probe object: fd = %d", fd
);
593 * Create a kernel event, enable it to the kernel tracer and add it to the
594 * channel event list of the kernel session.
595 * We own filter_expression and filter.
597 int kernel_create_event(struct lttng_event
*ev
,
598 struct ltt_kernel_channel
*channel
,
599 char *filter_expression
,
600 struct lttng_bytecode
*filter
)
603 enum lttng_error_code ret
;
604 struct ltt_kernel_event
*event
;
607 LTTNG_ASSERT(channel
);
609 /* We pass ownership of filter_expression and filter */
610 ret
= trace_kernel_create_event(ev
, filter_expression
, filter
, &event
);
611 if (ret
!= LTTNG_OK
) {
615 fd
= kernctl_create_event(channel
->fd
, event
->event
);
619 ret
= LTTNG_ERR_KERN_EVENT_EXIST
;
622 WARN("Event type not implemented");
623 ret
= LTTNG_ERR_KERN_EVENT_ENOSYS
;
626 WARN("Event %s not found!", ev
->name
);
627 ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
630 ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
631 PERROR("create event ioctl");
636 event
->type
= ev
->type
;
638 /* Prevent fd duplication after execlp() */
639 err
= fcntl(event
->fd
, F_SETFD
, FD_CLOEXEC
);
641 PERROR("fcntl session fd");
645 err
= kernctl_filter(event
->fd
, filter
);
649 ret
= LTTNG_ERR_FILTER_NOMEM
;
652 ret
= LTTNG_ERR_FILTER_INVAL
;
659 if (ev
->type
== LTTNG_EVENT_USERSPACE_PROBE
) {
660 ret
= (lttng_error_code
) userspace_probe_event_add_callsites(
661 ev
, channel
->session
, event
->fd
);
663 goto add_callsite_error
;
667 err
= kernctl_enable(event
->fd
);
671 ret
= LTTNG_ERR_KERN_EVENT_EXIST
;
674 PERROR("enable kernel event");
675 ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
681 /* Add event to event list */
682 cds_list_add(&event
->list
, &channel
->events_list
.head
);
683 channel
->event_count
++;
685 DBG("Event %s created (fd: %d)", ev
->name
, event
->fd
);
695 closeret
= close(event
->fd
);
697 PERROR("close event fd");
707 * Disable a kernel channel.
709 int kernel_disable_channel(struct ltt_kernel_channel
*chan
)
715 ret
= kernctl_disable(chan
->fd
);
717 PERROR("disable chan ioctl");
721 chan
->enabled
= false;
722 DBG("Kernel channel %s disabled (fd: %d, key: %" PRIu64
")",
734 * Enable a kernel channel.
736 int kernel_enable_channel(struct ltt_kernel_channel
*chan
)
742 ret
= kernctl_enable(chan
->fd
);
743 if (ret
< 0 && ret
!= -EEXIST
) {
744 PERROR("Enable kernel chan");
748 chan
->enabled
= true;
749 DBG("Kernel channel %s enabled (fd: %d, key: %" PRIu64
")",
761 * Enable a kernel event.
763 int kernel_enable_event(struct ltt_kernel_event
*event
)
769 ret
= kernctl_enable(event
->fd
);
773 ret
= LTTNG_ERR_KERN_EVENT_EXIST
;
776 PERROR("enable kernel event");
782 event
->enabled
= true;
783 DBG("Kernel event %s enabled (fd: %d)", event
->event
->name
, event
->fd
);
792 * Disable a kernel event.
794 int kernel_disable_event(struct ltt_kernel_event
*event
)
800 ret
= kernctl_disable(event
->fd
);
802 PERROR("Failed to disable kernel event: name = '%s', fd = %d",
808 event
->enabled
= false;
809 DBG("Kernel event %s disabled (fd: %d)", event
->event
->name
, event
->fd
);
818 * Disable a kernel event notifier.
820 static int kernel_disable_event_notifier_rule(struct ltt_kernel_event_notifier_rule
*event
)
826 lttng::urcu::read_lock_guard read_lock
;
827 cds_lfht_del(kernel_token_to_event_notifier_rule_ht
, &event
->ht_node
);
829 ret
= kernctl_disable(event
->fd
);
831 PERROR("Failed to disable kernel event notifier: fd = %d, token = %" PRIu64
,
837 event
->enabled
= false;
838 DBG("Disabled kernel event notifier: fd = %d, token = %" PRIu64
, event
->fd
, event
->token
);
844 static struct process_attr_tracker
*
845 _kernel_get_process_attr_tracker(struct ltt_kernel_session
*session
,
846 enum lttng_process_attr process_attr
)
848 switch (process_attr
) {
849 case LTTNG_PROCESS_ATTR_PROCESS_ID
:
850 return session
->tracker_pid
;
851 case LTTNG_PROCESS_ATTR_VIRTUAL_PROCESS_ID
:
852 return session
->tracker_vpid
;
853 case LTTNG_PROCESS_ATTR_USER_ID
:
854 return session
->tracker_uid
;
855 case LTTNG_PROCESS_ATTR_VIRTUAL_USER_ID
:
856 return session
->tracker_vuid
;
857 case LTTNG_PROCESS_ATTR_GROUP_ID
:
858 return session
->tracker_gid
;
859 case LTTNG_PROCESS_ATTR_VIRTUAL_GROUP_ID
:
860 return session
->tracker_vgid
;
866 const struct process_attr_tracker
*
867 kernel_get_process_attr_tracker(struct ltt_kernel_session
*session
,
868 enum lttng_process_attr process_attr
)
870 return (const struct process_attr_tracker
*) _kernel_get_process_attr_tracker(session
,
874 enum lttng_error_code
875 kernel_process_attr_tracker_set_tracking_policy(struct ltt_kernel_session
*session
,
876 enum lttng_process_attr process_attr
,
877 enum lttng_tracking_policy policy
)
880 enum lttng_error_code ret_code
= LTTNG_OK
;
881 struct process_attr_tracker
*tracker
=
882 _kernel_get_process_attr_tracker(session
, process_attr
);
883 enum lttng_tracking_policy previous_policy
;
886 ret_code
= LTTNG_ERR_INVALID
;
890 previous_policy
= process_attr_tracker_get_tracking_policy(tracker
);
891 ret
= process_attr_tracker_set_tracking_policy(tracker
, policy
);
893 ret_code
= LTTNG_ERR_UNK
;
897 if (previous_policy
== policy
) {
902 case LTTNG_TRACKING_POLICY_INCLUDE_ALL
:
903 if (process_attr
== LTTNG_PROCESS_ATTR_PROCESS_ID
) {
905 * Maintain a special case for the process ID process
906 * attribute tracker as it was the only supported
907 * attribute prior to 2.12.
909 ret
= kernctl_track_pid(session
->fd
, -1);
911 ret
= kernctl_track_id(session
->fd
, process_attr
, -1);
914 case LTTNG_TRACKING_POLICY_EXCLUDE_ALL
:
915 case LTTNG_TRACKING_POLICY_INCLUDE_SET
:
917 if (process_attr
== LTTNG_PROCESS_ATTR_PROCESS_ID
) {
919 * Maintain a special case for the process ID process
920 * attribute tracker as it was the only supported
921 * attribute prior to 2.12.
923 ret
= kernctl_untrack_pid(session
->fd
, -1);
925 ret
= kernctl_untrack_id(session
->fd
, process_attr
, -1);
931 /* kern-ctl error handling */
937 ret_code
= LTTNG_ERR_INVALID
;
940 ret_code
= LTTNG_ERR_NOMEM
;
943 ret_code
= LTTNG_ERR_PROCESS_ATTR_EXISTS
;
946 ret_code
= LTTNG_ERR_UNK
;
953 enum lttng_error_code
954 kernel_process_attr_tracker_inclusion_set_add_value(struct ltt_kernel_session
*session
,
955 enum lttng_process_attr process_attr
,
956 const struct process_attr_value
*value
)
958 int ret
, integral_value
;
959 enum lttng_error_code ret_code
;
960 struct process_attr_tracker
*tracker
;
961 enum process_attr_tracker_status status
;
964 * Convert process attribute tracker value to the integral
965 * representation required by the kern-ctl API.
967 switch (process_attr
) {
968 case LTTNG_PROCESS_ATTR_PROCESS_ID
:
969 case LTTNG_PROCESS_ATTR_VIRTUAL_PROCESS_ID
:
970 integral_value
= (int) value
->value
.pid
;
972 case LTTNG_PROCESS_ATTR_USER_ID
:
973 case LTTNG_PROCESS_ATTR_VIRTUAL_USER_ID
:
974 if (value
->type
== LTTNG_PROCESS_ATTR_VALUE_TYPE_USER_NAME
) {
977 ret_code
= utils_user_id_from_name(value
->value
.user_name
, &uid
);
978 if (ret_code
!= LTTNG_OK
) {
981 integral_value
= (int) uid
;
983 integral_value
= (int) value
->value
.uid
;
986 case LTTNG_PROCESS_ATTR_GROUP_ID
:
987 case LTTNG_PROCESS_ATTR_VIRTUAL_GROUP_ID
:
988 if (value
->type
== LTTNG_PROCESS_ATTR_VALUE_TYPE_GROUP_NAME
) {
991 ret_code
= utils_group_id_from_name(value
->value
.group_name
, &gid
);
992 if (ret_code
!= LTTNG_OK
) {
995 integral_value
= (int) gid
;
997 integral_value
= (int) value
->value
.gid
;
1001 ret_code
= LTTNG_ERR_INVALID
;
1005 tracker
= _kernel_get_process_attr_tracker(session
, process_attr
);
1007 ret_code
= LTTNG_ERR_INVALID
;
1011 status
= process_attr_tracker_inclusion_set_add_value(tracker
, value
);
1012 if (status
!= PROCESS_ATTR_TRACKER_STATUS_OK
) {
1014 case PROCESS_ATTR_TRACKER_STATUS_EXISTS
:
1015 ret_code
= LTTNG_ERR_PROCESS_ATTR_EXISTS
;
1017 case PROCESS_ATTR_TRACKER_STATUS_INVALID_TRACKING_POLICY
:
1018 ret_code
= LTTNG_ERR_PROCESS_ATTR_TRACKER_INVALID_TRACKING_POLICY
;
1020 case PROCESS_ATTR_TRACKER_STATUS_ERROR
:
1022 ret_code
= LTTNG_ERR_UNK
;
1028 DBG("Kernel track %s %d for session id %" PRIu64
,
1029 lttng_process_attr_to_string(process_attr
),
1032 if (process_attr
== LTTNG_PROCESS_ATTR_PROCESS_ID
) {
1034 * Maintain a special case for the process ID process attribute
1035 * tracker as it was the only supported attribute prior to 2.12.
1037 ret
= kernctl_track_pid(session
->fd
, integral_value
);
1039 ret
= kernctl_track_id(session
->fd
, process_attr
, integral_value
);
1042 ret_code
= LTTNG_OK
;
1046 kernel_wait_quiescent();
1048 /* kern-ctl error handling */
1051 ret_code
= LTTNG_OK
;
1054 ret_code
= LTTNG_ERR_INVALID
;
1057 ret_code
= LTTNG_ERR_NOMEM
;
1060 ret_code
= LTTNG_ERR_PROCESS_ATTR_EXISTS
;
1063 ret_code
= LTTNG_ERR_UNK
;
1067 /* Attempt to remove the value from the tracker. */
1068 status
= process_attr_tracker_inclusion_set_remove_value(tracker
, value
);
1069 if (status
!= PROCESS_ATTR_TRACKER_STATUS_OK
) {
1070 ERR("Failed to roll-back the tracking of kernel %s process attribute %d while handling a kern-ctl error",
1071 lttng_process_attr_to_string(process_attr
),
1078 enum lttng_error_code
1079 kernel_process_attr_tracker_inclusion_set_remove_value(struct ltt_kernel_session
*session
,
1080 enum lttng_process_attr process_attr
,
1081 const struct process_attr_value
*value
)
1083 int ret
, integral_value
;
1084 enum lttng_error_code ret_code
;
1085 struct process_attr_tracker
*tracker
;
1086 enum process_attr_tracker_status status
;
1089 * Convert process attribute tracker value to the integral
1090 * representation required by the kern-ctl API.
1092 switch (process_attr
) {
1093 case LTTNG_PROCESS_ATTR_PROCESS_ID
:
1094 case LTTNG_PROCESS_ATTR_VIRTUAL_PROCESS_ID
:
1095 integral_value
= (int) value
->value
.pid
;
1097 case LTTNG_PROCESS_ATTR_USER_ID
:
1098 case LTTNG_PROCESS_ATTR_VIRTUAL_USER_ID
:
1099 if (value
->type
== LTTNG_PROCESS_ATTR_VALUE_TYPE_USER_NAME
) {
1102 ret_code
= utils_user_id_from_name(value
->value
.user_name
, &uid
);
1103 if (ret_code
!= LTTNG_OK
) {
1106 integral_value
= (int) uid
;
1108 integral_value
= (int) value
->value
.uid
;
1111 case LTTNG_PROCESS_ATTR_GROUP_ID
:
1112 case LTTNG_PROCESS_ATTR_VIRTUAL_GROUP_ID
:
1113 if (value
->type
== LTTNG_PROCESS_ATTR_VALUE_TYPE_GROUP_NAME
) {
1116 ret_code
= utils_group_id_from_name(value
->value
.group_name
, &gid
);
1117 if (ret_code
!= LTTNG_OK
) {
1120 integral_value
= (int) gid
;
1122 integral_value
= (int) value
->value
.gid
;
1126 ret_code
= LTTNG_ERR_INVALID
;
1130 tracker
= _kernel_get_process_attr_tracker(session
, process_attr
);
1132 ret_code
= LTTNG_ERR_INVALID
;
1136 status
= process_attr_tracker_inclusion_set_remove_value(tracker
, value
);
1137 if (status
!= PROCESS_ATTR_TRACKER_STATUS_OK
) {
1139 case PROCESS_ATTR_TRACKER_STATUS_MISSING
:
1140 ret_code
= LTTNG_ERR_PROCESS_ATTR_MISSING
;
1142 case PROCESS_ATTR_TRACKER_STATUS_INVALID_TRACKING_POLICY
:
1143 ret_code
= LTTNG_ERR_PROCESS_ATTR_TRACKER_INVALID_TRACKING_POLICY
;
1145 case PROCESS_ATTR_TRACKER_STATUS_ERROR
:
1147 ret_code
= LTTNG_ERR_UNK
;
1153 DBG("Kernel track %s %d for session id %" PRIu64
,
1154 lttng_process_attr_to_string(process_attr
),
1157 if (process_attr
== LTTNG_PROCESS_ATTR_PROCESS_ID
) {
1159 * Maintain a special case for the process ID process attribute
1160 * tracker as it was the only supported attribute prior to 2.12.
1162 ret
= kernctl_untrack_pid(session
->fd
, integral_value
);
1164 ret
= kernctl_untrack_id(session
->fd
, process_attr
, integral_value
);
1167 ret_code
= LTTNG_OK
;
1170 kernel_wait_quiescent();
1172 /* kern-ctl error handling */
1175 ret_code
= LTTNG_OK
;
1178 ret_code
= LTTNG_ERR_INVALID
;
1181 ret_code
= LTTNG_ERR_NOMEM
;
1184 ret_code
= LTTNG_ERR_PROCESS_ATTR_MISSING
;
1187 ret_code
= LTTNG_ERR_UNK
;
1191 /* Attempt to add the value to the tracker. */
1192 status
= process_attr_tracker_inclusion_set_add_value(tracker
, value
);
1193 if (status
!= PROCESS_ATTR_TRACKER_STATUS_OK
) {
1194 ERR("Failed to roll-back the tracking of kernel %s process attribute %d while handling a kern-ctl error",
1195 lttng_process_attr_to_string(process_attr
),
1203 * Create kernel metadata, open from the kernel tracer and add it to the
1206 int kernel_open_metadata(struct ltt_kernel_session
*session
)
1209 struct ltt_kernel_metadata
*lkm
= nullptr;
1211 LTTNG_ASSERT(session
);
1213 /* Allocate kernel metadata */
1214 lkm
= trace_kernel_create_metadata();
1215 if (lkm
== nullptr) {
1219 /* Kernel tracer metadata creation */
1220 ret
= kernctl_open_metadata(session
->fd
, &lkm
->conf
->attr
);
1226 lkm
->key
= ++next_kernel_channel_key
;
1227 /* Prevent fd duplication after execlp() */
1228 ret
= fcntl(lkm
->fd
, F_SETFD
, FD_CLOEXEC
);
1230 PERROR("fcntl session fd");
1233 session
->metadata
= lkm
;
1235 DBG("Kernel metadata opened (fd: %d)", lkm
->fd
);
1240 trace_kernel_destroy_metadata(lkm
);
1246 * Start tracing session.
1248 int kernel_start_session(struct ltt_kernel_session
*session
)
1252 LTTNG_ASSERT(session
);
1254 ret
= kernctl_start_session(session
->fd
);
1256 PERROR("ioctl start session");
1260 DBG("Kernel session started");
1269 * Make a kernel wait to make sure in-flight probe have completed.
1271 void kernel_wait_quiescent()
1274 int fd
= kernel_tracer_fd
;
1276 DBG("Kernel quiescent wait on %d", fd
);
1278 ret
= kernctl_wait_quiescent(fd
);
1280 PERROR("wait quiescent ioctl");
1281 ERR("Kernel quiescent wait failed");
1286 * Force flush buffer of metadata.
1288 int kernel_metadata_flush_buffer(int fd
)
1292 DBG("Kernel flushing metadata buffer on fd %d", fd
);
1294 ret
= kernctl_buffer_flush(fd
);
1296 ERR("Fail to flush metadata buffers %d (ret: %d)", fd
, ret
);
1303 * Force flush buffer for channel.
1305 int kernel_flush_buffer(struct ltt_kernel_channel
*channel
)
1308 struct ltt_kernel_stream
*stream
;
1310 LTTNG_ASSERT(channel
);
1312 DBG("Flush buffer for channel %s", channel
->channel
->name
);
1314 cds_list_for_each_entry (stream
, &channel
->stream_list
.head
, list
) {
1315 DBG("Flushing channel stream %d", stream
->fd
);
1316 ret
= kernctl_buffer_flush(stream
->fd
);
1319 ERR("Fail to flush buffer for stream %d (ret: %d)", stream
->fd
, ret
);
1327 * Stop tracing session.
1329 int kernel_stop_session(struct ltt_kernel_session
*session
)
1333 LTTNG_ASSERT(session
);
1335 ret
= kernctl_stop_session(session
->fd
);
1340 DBG("Kernel session stopped");
1349 * Open stream of channel, register it to the kernel tracer and add it
1350 * to the stream list of the channel.
1352 * Note: given that the streams may appear in random order wrt CPU
1353 * number (e.g. cpu hotplug), the index value of the stream number in
1354 * the stream name is not necessarily linked to the CPU number.
1356 * Return the number of created stream. Else, a negative value.
1358 int kernel_open_channel_stream(struct ltt_kernel_channel
*channel
)
1361 struct ltt_kernel_stream
*lks
;
1363 LTTNG_ASSERT(channel
);
1365 while ((ret
= kernctl_create_stream(channel
->fd
)) >= 0) {
1366 lks
= trace_kernel_create_stream(channel
->channel
->name
, channel
->stream_count
);
1367 if (lks
== nullptr) {
1376 /* Prevent fd duplication after execlp() */
1377 ret
= fcntl(lks
->fd
, F_SETFD
, FD_CLOEXEC
);
1379 PERROR("fcntl session fd");
1382 lks
->tracefile_size
= channel
->channel
->attr
.tracefile_size
;
1383 lks
->tracefile_count
= channel
->channel
->attr
.tracefile_count
;
1385 /* Add stream to channel stream list */
1386 cds_list_add(&lks
->list
, &channel
->stream_list
.head
);
1387 channel
->stream_count
++;
1389 DBG("Kernel stream %s created (fd: %d, state: %d)", lks
->name
, lks
->fd
, lks
->state
);
1392 return channel
->stream_count
;
1399 * Open the metadata stream and set it to the kernel session.
1401 int kernel_open_metadata_stream(struct ltt_kernel_session
*session
)
1405 LTTNG_ASSERT(session
);
1407 ret
= kernctl_create_stream(session
->metadata
->fd
);
1409 PERROR("kernel create metadata stream");
1413 DBG("Kernel metadata stream created (fd: %d)", ret
);
1414 session
->metadata_stream_fd
= ret
;
1415 /* Prevent fd duplication after execlp() */
1416 ret
= fcntl(session
->metadata_stream_fd
, F_SETFD
, FD_CLOEXEC
);
1418 PERROR("fcntl session fd");
1428 * Get the event list from the kernel tracer and return the number of elements.
1430 ssize_t
kernel_list_events(struct lttng_event
**events
)
1434 size_t nbmem
, count
= 0;
1436 struct lttng_event
*elist
;
1438 LTTNG_ASSERT(events
);
1440 fd
= kernctl_tracepoint_list(kernel_tracer_fd
);
1442 PERROR("kernel tracepoint list");
1446 fp
= fdopen(fd
, "r");
1447 if (fp
== nullptr) {
1448 PERROR("kernel tracepoint list fdopen");
1453 * Init memory size counter
1454 * See kernel-ctl.h for explanation of this value
1456 nbmem
= KERNEL_EVENT_INIT_LIST_SIZE
;
1457 elist
= calloc
<lttng_event
>(nbmem
);
1458 if (elist
== nullptr) {
1459 PERROR("alloc list events");
1464 while (fscanf(fp
, "event { name = %m[^;]; };\n", &event
) == 1) {
1465 if (count
>= nbmem
) {
1466 struct lttng_event
*new_elist
;
1469 new_nbmem
= nbmem
<< 1;
1470 DBG("Reallocating event list from %zu to %zu bytes", nbmem
, new_nbmem
);
1471 new_elist
= (lttng_event
*) realloc(elist
,
1472 new_nbmem
* sizeof(struct lttng_event
));
1473 if (new_elist
== nullptr) {
1474 PERROR("realloc list events");
1480 /* Zero the new memory */
1481 memset(new_elist
+ nbmem
,
1483 (new_nbmem
- nbmem
) * sizeof(struct lttng_event
));
1487 strncpy(elist
[count
].name
, event
, LTTNG_SYMBOL_NAME_LEN
);
1488 elist
[count
].name
[LTTNG_SYMBOL_NAME_LEN
- 1] = '\0';
1489 elist
[count
].enabled
= -1;
1495 DBG("Kernel list events done (%zu events)", count
);
1497 ret
= fclose(fp
); /* closes both fp and fd */
1513 * Get kernel version and validate it.
1515 int kernel_validate_version(struct lttng_kernel_abi_tracer_version
*version
,
1516 struct lttng_kernel_abi_tracer_abi_version
*abi_version
)
1520 ret
= kernctl_tracer_version(kernel_tracer_fd
, version
);
1522 ERR("Failed to retrieve the lttng-modules version");
1526 /* Validate version */
1527 if (version
->major
!= VERSION_MAJOR
) {
1528 ERR("Kernel tracer major version (%d) is not compatible with lttng-tools major version (%d)",
1533 ret
= kernctl_tracer_abi_version(kernel_tracer_fd
, abi_version
);
1535 ERR("Failed to retrieve lttng-modules ABI version");
1538 if (abi_version
->major
!= LTTNG_KERNEL_ABI_MAJOR_VERSION
) {
1539 ERR("Kernel tracer ABI version (%d.%d) does not match the expected ABI major version (%d.*)",
1542 LTTNG_KERNEL_ABI_MAJOR_VERSION
);
1545 DBG2("Kernel tracer version validated (%d.%d, ABI %d.%d)",
1549 abi_version
->minor
);
1556 ERR("Kernel tracer version check failed; kernel tracing will not be available");
1561 * Kernel work-arounds called at the start of sessiond main().
1563 int init_kernel_workarounds()
1569 * boot_id needs to be read once before being used concurrently
1570 * to deal with a Linux kernel race. A fix is proposed for
1571 * upstream, but the work-around is needed for older kernels.
1573 fp
= fopen("/proc/sys/kernel/random/boot_id", "r");
1580 ret
= fread(buf
, 1, sizeof(buf
), fp
);
1582 /* Ignore error, we don't really care */
1594 * Teardown of a kernel session, keeping data required by destroy notifiers.
1596 void kernel_destroy_session(struct ltt_kernel_session
*ksess
)
1598 struct lttng_trace_chunk
*trace_chunk
;
1600 if (ksess
== nullptr) {
1601 DBG3("No kernel session when tearing down session");
1605 DBG("Tearing down kernel session");
1606 trace_chunk
= ksess
->current_trace_chunk
;
1609 * Destroy channels on the consumer if at least one FD has been sent and we
1610 * are in no output mode because the streams are in *no* monitor mode so we
1611 * have to send a command to clean them up or else they leaked.
1613 if (!ksess
->output_traces
&& ksess
->consumer_fds_sent
) {
1615 struct consumer_socket
*socket
;
1616 struct lttng_ht_iter iter
;
1618 /* For each consumer socket. */
1619 lttng::urcu::read_lock_guard read_lock
;
1621 cds_lfht_for_each_entry (
1622 ksess
->consumer
->socks
->ht
, &iter
.iter
, socket
, node
.node
) {
1623 struct ltt_kernel_channel
*chan
;
1625 /* For each channel, ask the consumer to destroy it. */
1626 cds_list_for_each_entry (chan
, &ksess
->channel_list
.head
, list
) {
1627 ret
= kernel_consumer_destroy_channel(socket
, chan
);
1629 /* Consumer is probably dead. Use next socket. */
1636 /* Close any relayd session */
1637 consumer_output_send_destroy_relayd(ksess
->consumer
);
1639 trace_kernel_destroy_session(ksess
);
1640 lttng_trace_chunk_put(trace_chunk
);
1643 /* Teardown of data required by destroy notifiers. */
1644 void kernel_free_session(struct ltt_kernel_session
*ksess
)
1646 if (ksess
== nullptr) {
1649 trace_kernel_free_session(ksess
);
1653 * Destroy a kernel channel object. It does not do anything on the tracer side.
1655 void kernel_destroy_channel(struct ltt_kernel_channel
*kchan
)
1657 struct ltt_kernel_session
*ksess
= nullptr;
1659 LTTNG_ASSERT(kchan
);
1660 LTTNG_ASSERT(kchan
->channel
);
1662 DBG3("Kernel destroy channel %s", kchan
->channel
->name
);
1664 /* Update channel count of associated session. */
1665 if (kchan
->session
) {
1666 /* Keep pointer reference so we can update it after the destroy. */
1667 ksess
= kchan
->session
;
1670 trace_kernel_destroy_channel(kchan
);
1673 * At this point the kernel channel is not visible anymore. This is safe
1674 * since in order to work on a visible kernel session, the tracing session
1675 * lock (ltt_session.lock) MUST be acquired.
1678 ksess
->channel_count
--;
1683 * Take a snapshot for a given kernel session.
1685 * Return LTTNG_OK on success or else return a LTTNG_ERR code.
1687 enum lttng_error_code
kernel_snapshot_record(struct ltt_kernel_session
*ksess
,
1688 const struct consumer_output
*output
,
1689 uint64_t nb_packets_per_stream
)
1691 int err
, ret
, saved_metadata_fd
;
1692 enum lttng_error_code status
= LTTNG_OK
;
1693 struct consumer_socket
*socket
;
1694 struct lttng_ht_iter iter
;
1695 struct ltt_kernel_metadata
*saved_metadata
;
1696 char *trace_path
= nullptr;
1697 size_t consumer_path_offset
= 0;
1699 LTTNG_ASSERT(ksess
);
1700 LTTNG_ASSERT(ksess
->consumer
);
1701 LTTNG_ASSERT(output
);
1703 DBG("Kernel snapshot record started");
1705 /* Save current metadata since the following calls will change it. */
1706 saved_metadata
= ksess
->metadata
;
1707 saved_metadata_fd
= ksess
->metadata_stream_fd
;
1709 ret
= kernel_open_metadata(ksess
);
1711 status
= LTTNG_ERR_KERN_META_FAIL
;
1715 ret
= kernel_open_metadata_stream(ksess
);
1717 status
= LTTNG_ERR_KERN_META_FAIL
;
1718 goto error_open_stream
;
1721 trace_path
= setup_channel_trace_path(ksess
->consumer
, "", &consumer_path_offset
);
1723 status
= LTTNG_ERR_INVALID
;
1728 /* Send metadata to consumer and snapshot everything. */
1729 lttng::urcu::read_lock_guard read_lock
;
1731 cds_lfht_for_each_entry (output
->socks
->ht
, &iter
.iter
, socket
, node
.node
) {
1732 struct ltt_kernel_channel
*chan
;
1734 pthread_mutex_lock(socket
->lock
);
1735 /* This stream must not be monitored by the consumer. */
1736 ret
= kernel_consumer_add_metadata(socket
, ksess
, 0);
1737 pthread_mutex_unlock(socket
->lock
);
1739 status
= LTTNG_ERR_KERN_META_FAIL
;
1740 goto error_consumer
;
1743 /* For each channel, ask the consumer to snapshot it. */
1744 cds_list_for_each_entry (chan
, &ksess
->channel_list
.head
, list
) {
1746 consumer_snapshot_channel(socket
,
1750 &trace_path
[consumer_path_offset
],
1751 nb_packets_per_stream
);
1752 if (status
!= LTTNG_OK
) {
1753 (void) kernel_consumer_destroy_metadata(socket
,
1755 goto error_consumer
;
1759 /* Snapshot metadata, */
1760 status
= consumer_snapshot_channel(socket
,
1761 ksess
->metadata
->key
,
1764 &trace_path
[consumer_path_offset
],
1766 if (status
!= LTTNG_OK
) {
1767 goto error_consumer
;
1771 * The metadata snapshot is done, ask the consumer to destroy it since
1772 * it's not monitored on the consumer side.
1774 (void) kernel_consumer_destroy_metadata(socket
, ksess
->metadata
);
1779 /* Close newly opened metadata stream. It's now on the consumer side. */
1780 err
= close(ksess
->metadata_stream_fd
);
1782 PERROR("close snapshot kernel");
1786 trace_kernel_destroy_metadata(ksess
->metadata
);
1788 /* Restore metadata state.*/
1789 ksess
->metadata
= saved_metadata
;
1790 ksess
->metadata_stream_fd
= saved_metadata_fd
;
1796 * Get the syscall mask array from the kernel tracer.
1798 * Return 0 on success else a negative value. In both case, syscall_mask should
1801 int kernel_syscall_mask(int chan_fd
, char **syscall_mask
, uint32_t *nr_bits
)
1803 LTTNG_ASSERT(syscall_mask
);
1804 LTTNG_ASSERT(nr_bits
);
1806 return kernctl_syscall_mask(chan_fd
, syscall_mask
, nr_bits
);
1809 static int kernel_tracer_abi_greater_or_equal(unsigned int major
, unsigned int minor
)
1812 struct lttng_kernel_abi_tracer_abi_version abi
;
1814 ret
= kernctl_tracer_abi_version(kernel_tracer_fd
, &abi
);
1816 ERR("Failed to retrieve lttng-modules ABI version");
1820 ret
= abi
.major
> major
|| (abi
.major
== major
&& abi
.minor
>= minor
);
1826 * Check for the support of the RING_BUFFER_SNAPSHOT_SAMPLE_POSITIONS via abi
1829 * Return 1 on success, 0 when feature is not supported, negative value in case
1832 int kernel_supports_ring_buffer_snapshot_sample_positions()
1835 * RING_BUFFER_SNAPSHOT_SAMPLE_POSITIONS was introduced in 2.3
1837 return kernel_tracer_abi_greater_or_equal(2, 3);
1841 * Check for the support of the packet sequence number via abi version number.
1843 * Return 1 on success, 0 when feature is not supported, negative value in case
1846 int kernel_supports_ring_buffer_packet_sequence_number()
1849 * Packet sequence number was introduced in LTTng 2.8,
1850 * lttng-modules ABI 2.1.
1852 return kernel_tracer_abi_greater_or_equal(2, 1);
1856 * Check for the support of event notifiers via abi version number.
1858 * Return 1 on success, 0 when feature is not supported, negative value in case
1861 int kernel_supports_event_notifiers()
1864 * Event notifiers were introduced in LTTng 2.13, lttng-modules ABI 2.6.
1866 return kernel_tracer_abi_greater_or_equal(2, 6);
1870 * Rotate a kernel session.
1872 * Return LTTNG_OK on success or else an LTTng error code.
1874 enum lttng_error_code
kernel_rotate_session(struct ltt_session
*session
)
1877 enum lttng_error_code status
= LTTNG_OK
;
1878 struct consumer_socket
*socket
;
1879 struct lttng_ht_iter iter
;
1880 struct ltt_kernel_session
*ksess
= session
->kernel_session
;
1882 LTTNG_ASSERT(ksess
);
1883 LTTNG_ASSERT(ksess
->consumer
);
1885 DBG("Rotate kernel session %s started (session %" PRIu64
")", session
->name
, session
->id
);
1889 * Note that this loop will end after one iteration given that there is
1890 * only one kernel consumer.
1892 lttng::urcu::read_lock_guard read_lock
;
1894 cds_lfht_for_each_entry (
1895 ksess
->consumer
->socks
->ht
, &iter
.iter
, socket
, node
.node
) {
1896 struct ltt_kernel_channel
*chan
;
1898 /* For each channel, ask the consumer to rotate it. */
1899 cds_list_for_each_entry (chan
, &ksess
->channel_list
.head
, list
) {
1900 DBG("Rotate kernel channel %" PRIu64
", session %s",
1903 ret
= consumer_rotate_channel(socket
,
1906 /* is_metadata_channel */ false);
1908 status
= LTTNG_ERR_ROTATION_FAIL_CONSUMER
;
1914 * Rotate the metadata channel.
1916 ret
= consumer_rotate_channel(socket
,
1917 ksess
->metadata
->key
,
1919 /* is_metadata_channel */ true);
1921 status
= LTTNG_ERR_ROTATION_FAIL_CONSUMER
;
1931 enum lttng_error_code
kernel_create_channel_subdirectories(const struct ltt_kernel_session
*ksess
)
1933 enum lttng_error_code ret
= LTTNG_OK
;
1934 enum lttng_trace_chunk_status chunk_status
;
1936 lttng::urcu::read_lock_guard read_lock
;
1937 LTTNG_ASSERT(ksess
->current_trace_chunk
);
1940 * Create the index subdirectory which will take care
1941 * of implicitly creating the channel's path.
1943 chunk_status
= lttng_trace_chunk_create_subdirectory(
1944 ksess
->current_trace_chunk
, DEFAULT_KERNEL_TRACE_DIR
"/" DEFAULT_INDEX_DIR
);
1945 if (chunk_status
!= LTTNG_TRACE_CHUNK_STATUS_OK
) {
1946 ret
= LTTNG_ERR_CREATE_DIR_FAIL
;
1954 * Setup necessary data for kernel tracer action.
1956 int init_kernel_tracer()
1959 bool is_root
= !getuid();
1961 /* Modprobe lttng kernel modules */
1962 ret
= modprobe_lttng_control();
1967 /* Open debugfs lttng */
1968 kernel_tracer_fd
= open(module_proc_lttng
, O_RDWR
);
1969 if (kernel_tracer_fd
< 0) {
1970 DBG("Failed to open %s", module_proc_lttng
);
1974 /* Validate kernel version */
1975 ret
= kernel_validate_version(&the_kernel_tracer_version
, &the_kernel_tracer_abi_version
);
1980 ret
= modprobe_lttng_data();
1985 ret
= kernel_supports_ring_buffer_snapshot_sample_positions();
1990 WARN("Kernel tracer does not support buffer monitoring. "
1991 "The monitoring timer of channels in the kernel domain "
1992 "will be set to 0 (disabled).");
1995 ret
= kernel_supports_event_notifiers();
1997 ERR("Failed to check for kernel tracer event notifier support");
2000 ret
= kernel_create_event_notifier_group(&kernel_tracer_event_notifier_group_fd
);
2002 /* This is not fatal. */
2003 WARN("Failed to create kernel event notifier group");
2004 kernel_tracer_event_notifier_group_fd
= -1;
2006 enum event_notifier_error_accounting_status error_accounting_status
;
2007 enum lttng_error_code error_code_ret
=
2008 kernel_create_event_notifier_group_notification_fd(
2009 &kernel_tracer_event_notifier_group_notification_fd
);
2011 if (error_code_ret
!= LTTNG_OK
) {
2015 error_accounting_status
= event_notifier_error_accounting_register_kernel(
2016 kernel_tracer_event_notifier_group_fd
);
2017 if (error_accounting_status
!= EVENT_NOTIFIER_ERROR_ACCOUNTING_STATUS_OK
) {
2018 ERR("Failed to initialize event notifier error accounting for kernel tracer");
2019 error_code_ret
= LTTNG_ERR_EVENT_NOTIFIER_ERROR_ACCOUNTING
;
2023 kernel_token_to_event_notifier_rule_ht
= cds_lfht_new(
2024 DEFAULT_HT_SIZE
, 1, 0, CDS_LFHT_AUTO_RESIZE
| CDS_LFHT_ACCOUNTING
, nullptr);
2025 if (!kernel_token_to_event_notifier_rule_ht
) {
2026 goto error_token_ht
;
2030 DBG("Kernel tracer initialized: kernel tracer fd = %d, event notifier group fd = %d, event notifier group notification fd = %d",
2032 kernel_tracer_event_notifier_group_fd
,
2033 kernel_tracer_event_notifier_group_notification_fd
);
2035 ret
= syscall_init_table(kernel_tracer_fd
);
2037 ERR("Unable to populate syscall table. Syscall tracing won't "
2038 "work for this session daemon.");
2044 modprobe_remove_lttng_control();
2045 ret
= close(kernel_tracer_fd
);
2047 PERROR("Failed to close kernel tracer file descriptor: fd = %d", kernel_tracer_fd
);
2050 kernel_tracer_fd
= -1;
2051 return LTTNG_ERR_KERN_VERSION
;
2054 ret
= close(kernel_tracer_event_notifier_group_notification_fd
);
2056 PERROR("Failed to close kernel tracer event notifier group notification file descriptor: fd = %d",
2057 kernel_tracer_event_notifier_group_notification_fd
);
2060 kernel_tracer_event_notifier_group_notification_fd
= -1;
2063 ret
= close(kernel_tracer_event_notifier_group_fd
);
2065 PERROR("Failed to close kernel tracer event notifier group file descriptor: fd = %d",
2066 kernel_tracer_event_notifier_group_fd
);
2069 kernel_tracer_event_notifier_group_fd
= -1;
2071 ret
= close(kernel_tracer_fd
);
2073 PERROR("Failed to close kernel tracer file descriptor: fd = %d", kernel_tracer_fd
);
2076 kernel_tracer_fd
= -1;
2079 modprobe_remove_lttng_control();
2082 WARN("No kernel tracer available");
2083 kernel_tracer_fd
= -1;
2085 return LTTNG_ERR_NEED_ROOT_SESSIOND
;
2087 return LTTNG_ERR_KERN_NA
;
2091 void cleanup_kernel_tracer()
2093 DBG2("Closing kernel event notifier group notification file descriptor");
2094 if (kernel_tracer_event_notifier_group_notification_fd
>= 0) {
2095 int ret
= notification_thread_command_remove_tracer_event_source(
2096 the_notification_thread_handle
,
2097 kernel_tracer_event_notifier_group_notification_fd
);
2098 if (ret
!= LTTNG_OK
) {
2099 ERR("Failed to remove kernel event notifier notification from notification thread");
2102 ret
= close(kernel_tracer_event_notifier_group_notification_fd
);
2104 PERROR("Failed to close kernel event notifier group notification file descriptor: fd = %d",
2105 kernel_tracer_event_notifier_group_notification_fd
);
2108 kernel_tracer_event_notifier_group_notification_fd
= -1;
2111 if (kernel_token_to_event_notifier_rule_ht
) {
2112 const int ret
= cds_lfht_destroy(kernel_token_to_event_notifier_rule_ht
, nullptr);
2113 LTTNG_ASSERT(ret
== 0);
2116 DBG2("Closing kernel event notifier group file descriptor");
2117 if (kernel_tracer_event_notifier_group_fd
>= 0) {
2118 const int ret
= close(kernel_tracer_event_notifier_group_fd
);
2121 PERROR("Failed to close kernel event notifier group file descriptor: fd = %d",
2122 kernel_tracer_event_notifier_group_fd
);
2125 kernel_tracer_event_notifier_group_fd
= -1;
2128 DBG2("Closing kernel fd");
2129 if (kernel_tracer_fd
>= 0) {
2130 const int ret
= close(kernel_tracer_fd
);
2133 PERROR("Failed to close kernel tracer file descriptor: fd = %d",
2137 kernel_tracer_fd
= -1;
2140 free(syscall_table
);
2143 bool kernel_tracer_is_initialized()
2145 return kernel_tracer_fd
>= 0;
2149 * Clear a kernel session.
2151 * Return LTTNG_OK on success or else an LTTng error code.
2153 enum lttng_error_code
kernel_clear_session(struct ltt_session
*session
)
2156 enum lttng_error_code status
= LTTNG_OK
;
2157 struct consumer_socket
*socket
;
2158 struct lttng_ht_iter iter
;
2159 struct ltt_kernel_session
*ksess
= session
->kernel_session
;
2161 LTTNG_ASSERT(ksess
);
2162 LTTNG_ASSERT(ksess
->consumer
);
2164 DBG("Clear kernel session %s (session %" PRIu64
")", session
->name
, session
->id
);
2166 if (ksess
->active
) {
2167 ERR("Expecting inactive session %s (%" PRIu64
")", session
->name
, session
->id
);
2168 status
= LTTNG_ERR_FATAL
;
2174 * Note that this loop will end after one iteration given that there is
2175 * only one kernel consumer.
2177 lttng::urcu::read_lock_guard read_lock
;
2179 cds_lfht_for_each_entry (
2180 ksess
->consumer
->socks
->ht
, &iter
.iter
, socket
, node
.node
) {
2181 struct ltt_kernel_channel
*chan
;
2183 /* For each channel, ask the consumer to clear it. */
2184 cds_list_for_each_entry (chan
, &ksess
->channel_list
.head
, list
) {
2185 DBG("Clear kernel channel %" PRIu64
", session %s",
2188 ret
= consumer_clear_channel(socket
, chan
->key
);
2194 if (!ksess
->metadata
) {
2196 * Nothing to do for the metadata.
2197 * This is a snapshot session.
2198 * The metadata is genererated on the fly.
2204 * Clear the metadata channel.
2205 * Metadata channel is not cleared per se but we still need to
2206 * perform a rotation operation on it behind the scene.
2208 ret
= consumer_clear_channel(socket
, ksess
->metadata
->key
);
2218 case LTTCOMM_CONSUMERD_RELAYD_CLEAR_DISALLOWED
:
2219 status
= LTTNG_ERR_CLEAR_RELAY_DISALLOWED
;
2222 status
= LTTNG_ERR_CLEAR_FAIL_CONSUMER
;
2229 enum lttng_error_code
2230 kernel_create_event_notifier_group_notification_fd(int *event_notifier_group_notification_fd
)
2232 int local_fd
= -1, ret
;
2233 enum lttng_error_code error_code_ret
;
2235 LTTNG_ASSERT(event_notifier_group_notification_fd
);
2237 ret
= kernctl_create_event_notifier_group_notification_fd(
2238 kernel_tracer_event_notifier_group_fd
);
2240 PERROR("Failed to create kernel event notifier group notification file descriptor");
2241 error_code_ret
= LTTNG_ERR_EVENT_NOTIFIER_GROUP_NOTIFICATION_FD
;
2247 /* Prevent fd duplication after execlp(). */
2248 ret
= fcntl(local_fd
, F_SETFD
, FD_CLOEXEC
);
2250 PERROR("Failed to set FD_CLOEXEC on kernel event notifier group notification file descriptor: fd = %d",
2252 error_code_ret
= LTTNG_ERR_EVENT_NOTIFIER_GROUP_NOTIFICATION_FD
;
2256 DBG("Created kernel notifier group notification file descriptor: fd = %d", local_fd
);
2257 error_code_ret
= LTTNG_OK
;
2258 *event_notifier_group_notification_fd
= local_fd
;
2262 if (local_fd
>= 0) {
2263 ret
= close(local_fd
);
2265 PERROR("Failed to close kernel event notifier group notification file descriptor: fd = %d",
2270 return error_code_ret
;
2273 enum lttng_error_code
2274 kernel_destroy_event_notifier_group_notification_fd(int event_notifier_group_notification_fd
)
2276 enum lttng_error_code ret_code
= LTTNG_OK
;
2278 DBG("Closing event notifier group notification file descriptor: fd = %d",
2279 event_notifier_group_notification_fd
);
2280 if (event_notifier_group_notification_fd
>= 0) {
2281 const int ret
= close(event_notifier_group_notification_fd
);
2283 PERROR("Failed to close event notifier group notification file descriptor: fd = %d",
2284 event_notifier_group_notification_fd
);
2291 static unsigned long hash_trigger(const struct lttng_trigger
*trigger
)
2293 const struct lttng_condition
*condition
= lttng_trigger_get_const_condition(trigger
);
2295 return lttng_condition_hash(condition
);
2298 static int match_trigger(struct cds_lfht_node
*node
, const void *key
)
2300 const struct ltt_kernel_event_notifier_rule
*event_notifier_rule
;
2301 const struct lttng_trigger
*trigger
= (lttng_trigger
*) key
;
2303 event_notifier_rule
=
2304 caa_container_of(node
, const struct ltt_kernel_event_notifier_rule
, ht_node
);
2306 return lttng_trigger_is_equal(trigger
, event_notifier_rule
->trigger
);
2309 static enum lttng_error_code
kernel_create_event_notifier_rule(
2310 struct lttng_trigger
*trigger
, const struct lttng_credentials
*creds
, uint64_t token
)
2312 int err
, fd
, ret
= 0;
2313 enum lttng_error_code error_code_ret
;
2314 enum lttng_condition_status condition_status
;
2315 enum lttng_condition_type condition_type
;
2316 enum lttng_event_rule_type event_rule_type
;
2317 struct ltt_kernel_event_notifier_rule
*event_notifier_rule
;
2318 struct lttng_kernel_abi_event_notifier kernel_event_notifier
= {};
2319 unsigned int capture_bytecode_count
= 0, i
;
2320 const struct lttng_condition
*condition
= nullptr;
2321 const struct lttng_event_rule
*event_rule
= nullptr;
2322 enum lttng_condition_status cond_status
;
2324 LTTNG_ASSERT(trigger
);
2326 condition
= lttng_trigger_get_const_condition(trigger
);
2327 LTTNG_ASSERT(condition
);
2329 condition_type
= lttng_condition_get_type(condition
);
2330 LTTNG_ASSERT(condition_type
== LTTNG_CONDITION_TYPE_EVENT_RULE_MATCHES
);
2332 /* Does not acquire a reference. */
2333 condition_status
= lttng_condition_event_rule_matches_get_rule(condition
, &event_rule
);
2334 LTTNG_ASSERT(condition_status
== LTTNG_CONDITION_STATUS_OK
);
2335 LTTNG_ASSERT(event_rule
);
2337 event_rule_type
= lttng_event_rule_get_type(event_rule
);
2338 LTTNG_ASSERT(event_rule_type
!= LTTNG_EVENT_RULE_TYPE_UNKNOWN
);
2340 error_code_ret
= trace_kernel_create_event_notifier_rule(
2343 lttng_condition_event_rule_matches_get_error_counter_index(condition
),
2344 &event_notifier_rule
);
2345 if (error_code_ret
!= LTTNG_OK
) {
2349 error_code_ret
= trace_kernel_init_event_notifier_from_event_rule(event_rule
,
2350 &kernel_event_notifier
);
2351 if (error_code_ret
!= LTTNG_OK
) {
2355 kernel_event_notifier
.event
.token
= event_notifier_rule
->token
;
2356 kernel_event_notifier
.error_counter_idx
=
2357 lttng_condition_event_rule_matches_get_error_counter_index(condition
);
2359 fd
= kernctl_create_event_notifier(kernel_tracer_event_notifier_group_fd
,
2360 &kernel_event_notifier
);
2364 error_code_ret
= LTTNG_ERR_KERN_EVENT_EXIST
;
2367 WARN("Failed to create kernel event notifier: not notifier type not implemented");
2368 error_code_ret
= LTTNG_ERR_KERN_EVENT_ENOSYS
;
2371 WARN("Failed to create kernel event notifier: not found: name = '%s'",
2372 kernel_event_notifier
.event
.name
);
2373 error_code_ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
2376 PERROR("Failed to create kernel event notifier: error code = %d, name = '%s'",
2378 kernel_event_notifier
.event
.name
);
2379 error_code_ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
2384 event_notifier_rule
->fd
= fd
;
2385 /* Prevent fd duplication after execlp(). */
2386 err
= fcntl(event_notifier_rule
->fd
, F_SETFD
, FD_CLOEXEC
);
2388 PERROR("Failed to set FD_CLOEXEC on kernel event notifier file descriptor: fd = %d",
2390 error_code_ret
= LTTNG_ERR_FATAL
;
2391 goto set_cloexec_error
;
2394 if (event_notifier_rule
->filter
) {
2395 err
= kernctl_filter(event_notifier_rule
->fd
, event_notifier_rule
->filter
);
2399 error_code_ret
= LTTNG_ERR_FILTER_NOMEM
;
2402 error_code_ret
= LTTNG_ERR_FILTER_INVAL
;
2409 if (lttng_event_rule_get_type(event_rule
) == LTTNG_EVENT_RULE_TYPE_KERNEL_UPROBE
) {
2410 ret
= userspace_probe_event_rule_add_callsites(
2411 event_rule
, creds
, event_notifier_rule
->fd
);
2413 error_code_ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
2414 goto add_callsite_error
;
2418 /* Set the capture bytecode if any. */
2419 cond_status
= lttng_condition_event_rule_matches_get_capture_descriptor_count(
2420 condition
, &capture_bytecode_count
);
2421 LTTNG_ASSERT(cond_status
== LTTNG_CONDITION_STATUS_OK
);
2423 for (i
= 0; i
< capture_bytecode_count
; i
++) {
2424 const struct lttng_bytecode
*capture_bytecode
=
2425 lttng_condition_event_rule_matches_get_capture_bytecode_at_index(condition
,
2428 if (capture_bytecode
== nullptr) {
2429 ERR("Unexpected NULL capture bytecode on condition");
2430 error_code_ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
2434 ret
= kernctl_capture(event_notifier_rule
->fd
, capture_bytecode
);
2436 ERR("Failed to set capture bytecode on event notifier rule fd: fd = %d",
2437 event_notifier_rule
->fd
);
2438 error_code_ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
2443 err
= kernctl_enable(event_notifier_rule
->fd
);
2447 error_code_ret
= LTTNG_ERR_KERN_EVENT_EXIST
;
2450 PERROR("enable kernel event notifier");
2451 error_code_ret
= LTTNG_ERR_KERN_ENABLE_FAIL
;
2457 /* Add trigger to kernel token mapping in the hash table. */
2459 lttng::urcu::read_lock_guard read_lock
;
2460 cds_lfht_add(kernel_token_to_event_notifier_rule_ht
,
2461 hash_trigger(trigger
),
2462 &event_notifier_rule
->ht_node
);
2465 DBG("Created kernel event notifier: name = '%s', fd = %d",
2466 kernel_event_notifier
.event
.name
,
2467 event_notifier_rule
->fd
);
2477 const int close_ret
= close(event_notifier_rule
->fd
);
2480 PERROR("Failed to close kernel event notifier file descriptor: fd = %d",
2481 event_notifier_rule
->fd
);
2485 free(event_notifier_rule
);
2487 return error_code_ret
;
2490 enum lttng_error_code
kernel_register_event_notifier(struct lttng_trigger
*trigger
,
2491 const struct lttng_credentials
*cmd_creds
)
2493 enum lttng_error_code ret
;
2494 enum lttng_condition_status status
;
2495 enum lttng_domain_type domain_type
;
2496 const struct lttng_event_rule
*event_rule
;
2497 const struct lttng_condition
*const condition
= lttng_trigger_get_const_condition(trigger
);
2498 const uint64_t token
= lttng_trigger_get_tracer_token(trigger
);
2500 LTTNG_ASSERT(condition
);
2502 /* Does not acquire a reference to the event rule. */
2503 status
= lttng_condition_event_rule_matches_get_rule(condition
, &event_rule
);
2504 LTTNG_ASSERT(status
== LTTNG_CONDITION_STATUS_OK
);
2506 domain_type
= lttng_event_rule_get_domain_type(event_rule
);
2507 LTTNG_ASSERT(domain_type
== LTTNG_DOMAIN_KERNEL
);
2509 ret
= kernel_create_event_notifier_rule(trigger
, cmd_creds
, token
);
2510 if (ret
!= LTTNG_OK
) {
2511 ERR("Failed to create kernel event notifier rule");
2517 enum lttng_error_code
kernel_unregister_event_notifier(const struct lttng_trigger
*trigger
)
2519 struct ltt_kernel_event_notifier_rule
*token_event_rule_element
;
2520 struct cds_lfht_node
*node
;
2521 struct cds_lfht_iter iter
;
2522 enum lttng_error_code error_code_ret
;
2525 lttng::urcu::read_lock_guard read_lock
;
2527 cds_lfht_lookup(kernel_token_to_event_notifier_rule_ht
,
2528 hash_trigger(trigger
),
2533 node
= cds_lfht_iter_get_node(&iter
);
2535 error_code_ret
= LTTNG_ERR_TRIGGER_NOT_FOUND
;
2539 token_event_rule_element
=
2540 caa_container_of(node
, struct ltt_kernel_event_notifier_rule
, ht_node
);
2542 ret
= kernel_disable_event_notifier_rule(token_event_rule_element
);
2544 error_code_ret
= LTTNG_ERR_FATAL
;
2548 trace_kernel_destroy_event_notifier_rule(token_event_rule_element
);
2549 error_code_ret
= LTTNG_OK
;
2553 return error_code_ret
;
2556 int kernel_get_notification_fd()
2558 return kernel_tracer_event_notifier_group_notification_fd
;